Adcs Template Abuse

Exploits misconfigured AD CS certificate templates to impersonate any domain user via SAN manipulation or enrollment agent abuse. Covers ESC1 (enrollee supplies subject), ESC2 (any-purpose/no EKU), ESC3 (enrollment agent), ESC6 (EDITF_ATTRIBUTESUBJECTALTNAME2 CA flag).

blacklanternsecurity ae9b138 15.6 KB Updated

File contents

blacklanternsecurity/red-run/tree/main/skills/ad/adcs-template-abuse commit ae9b138a2f

Frequently asked questions

npx skillmds@latest add blacklanternsecurity/adcs-template-abuse